CVE-2020-12101
30.04.2020, 14:15
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.Enginsight
Vendor | Product | Version |
---|---|---|
xt-commerce | xt-commerce | 5.1.0 ≤ 𝑥 ≤ 6.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References